Privacy Policy

Privacy Notice 

LAFS LEGAL CO., LTD. 

 

LAFS Legal Co., Ltd. (the “Company”) recognizes the importance of protecting personal data and maintaining the confidentiality of clients, persons seeking legal consultation, contractual parties, visitors, website users, and other persons connected with the Company’s legal services (collectively, the “Clients”). 
The Company has therefore prepared this Privacy Notice to explain how it collects, uses, discloses, transfers, and retains the personal data of Clients, as well as the rights of Clients under the Personal Data Protection Act B.E. 2562 (2019) and other applicable laws. 

Please read this Privacy Notice before providing personal data to the Company or using the Company’s services, website, or communication channels. 

 

1.Scope of Application 
This Privacy Notice applies to the personal data of persons who contact or have a relationship with the Company, including but not limited to:

  1. Current and former Clients 
  2. Persons who contact the Company to request consultation or inquire about legal services 
  3. Contractual parties, vendors, service providers, and external professionals 
  4. Opposing parties, witnesses, attorneys-in-fact, beneficiaries, estate administrators, heirs, or other persons involved in legal matters 
  5. Directors, shareholders, employees, or representatives of corporate clients 
  6. Office visitors and participants in meetings, seminars, or Company activities 
  7. Visitors to the Company’s website or social media channels and 
  8. Job applicants, interns and referees. 

This Privacy Notice does not apply to information relating solely to a juristic person, which is not considered personal data under applicable law, unless such information can be linked to an identifiable natural person.

 

2. Definitions 

2.1 Personal Data 
Information relating to a natural person that enables the identification of that person, whether directly or indirectly, but excluding information relating specifically to a deceased person. 

2.2 Sensitive Personal Data 
Personal data relating to race, ethnicity, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data or any other data prescribed by law. 

2.3 Processing of Personal Data 
Any operation performed on personal data, including collection, recording, organization, use, alteration, disclosure, transmission, storage, deletion, destruction or anonymization. 

2.4 Data Subject 
A natural person who can be identified by the relevant personal data. 

 

3. Personal Data the Company May Collect 
The categories of personal data collected by the Company depend on the nature of the relationship and the services requested by the Clients and may include the following: 

3.1 Identification Data 

  • First name, surname, former names, and other names previously used 
  • Date of birth, age, gender, and nationality 
  • Photographs, signatures, and specimen signatures 
  • National identification number 
  • Passport number 
  • Tax identification number 
  • Work permit number or foreigner identification number 
  • Copies of identification cards, passports, house registration documents or other official documents. 

3.2 Contact Data 

  • Registered address and current address 
  • Telephone number 
  • Email address 
  • Messaging application account 
  • Social media account 
  • Emergency contact details 

3.3 Family and Relationship Data 

  • Marital status 
  • Information concerning a spouse, partner, children, parents or relatives 
  • Birth certificates, marriage certificates, divorce certificates, or documents evidencing relationships 
  • Information concerning heirs, beneficiaries, estate administrators, or legal representatives. 

3.4 Financial and Asset Data 

  • Bank account numbers and payment information 
  • Evidence of money transfers 
  • Income, tax, debt, or source-of-funds information 
  • Details of real estate, condominium units, land, buildings, or other structures 
  • Details of shares, businesses, investments, vehicles, or other assets 
  • Purchase prices, appraised values, encumbrances, mortgages, or rights in property. 

The Company will not ask Clients to disclose passwords, PINs, or one-time passwords (OTPs) for their bank accounts. 

3.5 Data Relating to Legal Services 

  • Facts and statements concerning cases or disputes 
  • Contracts, powers of attorney, wills, or other legal documents 
  • Supporting documents for petitions, claims, defenses, or applications submitted to authorities 
  • Information concerning opposing parties, witnesses, beneficiaries, or other persons involved 
  • Case numbers, judgments, orders, or court documents 
  • Corporate, shareholding, investment, or business-license documents 
  • Information concerning visas, residence, employment, or immigration Information concerning the sale, purchase, lease, mortgage, or
  • transfer of real estate 
  • Legal opinions, advice, and communications between the Clients and the Company. 

Such information may include legally privileged information or information subject to a lawyer’s professional duty of confidentiality. 

3.6 Sensitive Personal Data 

  • For certain types of legal services, the Company may need to collect data such as: 
  • Health or disability information 
  • Biometric data appearing in official documents 
  • Religious information appearing in identification or family documents 
  • Criminal records or information concerning criminal proceedings 
  • Race or ethnicity information 
  • Information concerning family life or sexual behavior where relevant to family proceedings or other legal matters. 

The Company will process such data where explicit consent has been obtained or where an exception under applicable law applies, including where processing is necessary for the establishment, exercise, performance or defense of legal claims. 

3.7 Communication and Website Usage Data 

  • Internet Protocol (IP) address 
  • Device type, operating system, and web browser 
  • Date and time of access 
  • Pages visited and duration of use 
  • Cookies and similar technologies 
  • Records of communications through website forms, email, telephone or social media. 

Details concerning cookies should be set out separately in the Company’s Cookie Policy. 

3.8 CCTV and Premises Access Data 

The Company may collect CCTV images, records of dates and times of entry, visitor information, or vehicle information for the security of persons, property, and the Company’s premises. 

3.9 Recruitment Data 

  • Curriculum vitae and personal history 
  • Educational and employment history 
  • Qualifications and professional licenses 
  • Interview results 
  • Referee information 
  • Salary information and expected remuneration.

 

4. Sources of Personal Data 

The Company may obtain personal data from the following sources: 

  1. Directly from the Client through meetings, interviews, telephone calls, email, forms, the website, or messaging applications 
  2. From persons appointed or authorized by the Client, such as a spouse, relative, representative, attorney-in-fact, employer or adviser 
  3. From the Company’s clients where the Client’s data is relevant to an engagement assigned to the Company 
  4. From opposing parties, witnesses, government authorities, courts, officials, or relevant agencies 
  5. From public databases, such as company affidavits, land registers, judgments, or official announcements 
  6. From external Clients, such as translators, valuers, accountants, auditors, or other professionals and 
  7. From websites, social media, or other sources lawfully made available to the public. 

Where a client provides the personal data of another person to the Company, the Client should inform that person of this Privacy Notice and confirms that the Client has the appropriate right or lawful basis to disclose such data to the Company. 

 

5. Purposes of Processing Personal Data 

5.1 Pre-Engagement Review 

  • Verifying the identity of the Client or contact person 
  • Conducting conflict-of-interest checks 
  • Assessing the scope of work and the Company’s ability to accept the engagement 
  • Preparing quotations, engagement letters, or fee agreements 
  • Conducting checks required under anti-money laundering laws or other applicable laws. 

5.2 Provision of Legal Services 

  • Providing legal advice and preparing legal opinions 
  • Reviewing facts and documents 
  • Drafting, revising, or negotiating contracts 
  • Conducting litigation or dispute resolution 
  • Communicating with courts, government authorities, Land Offices, Immigration Offices, or other agencies 
  • Handling corporate, investment, tax, real estate, family, estate, or immigration matters 
  • Coordinating with contractual parties, opposing parties, witnesses, experts, or other advisers 
  • Acting under the powers of attorney or instructions given by Clients. 

5.3 Service Recipient Relationship Management 

  • Communicating, arranging appointments, and responding to inquiries 
  • Providing updates on the progress of matters 
  • Creating and retaining Client’s files 
  • Issuing invoices and receipts and following up on payment of professional fees 
  • Receiving feedback, handling complaints, or assessing satisfaction 
  • Reviewing and improving service quality. 

5.4 Administration and Security 

  • Administering information systems and access controls 
  • Preventing fraud, misconduct, or cybersecurity threats 
  • Maintaining the security of the office, personnel, and assets 
  • Investigating complaints or security incidents 
  • Backing up data and maintaining business continuity plans. 

5.5 Legal Compliance 

  • Complying with court orders, summonses, or lawful requests from government authorities 
  • Complying with tax, accounting, labor, and professional laws 
  • Complying with legal document-retention obligations 
  • Establishing, exercising, performing, or defending legal claims. 

5.6 Public Relations and Marketing 
Where consent has been obtained or another appropriate lawful basis applies, the Company may use personal data to: 
Send news, legal articles, or service information 

  • Invite Clients to seminars, events, or training sessions 
  • Offer services that may be relevant to the interests of Clients 
  • Analyze the performance of the Company’s website and public relations activities. 

Clients may unsubscribe from marketing communications through the channel stated in the relevant message or by contacting the Company directly. 

5.7 Recruitment and Human Resources Administration 

  • Assessing applicants’ qualifications 
  • Communicating with applicants and arranging interviews 
  • Conducting reference checks 
  • Preparing employment offers 
  • Complying with labor and other applicable laws. 

 

6. Lawful Bases for Processing 

6.1 Performance of a Contract 
Where processing is necessary to take steps at the request of the Client before entering into a contract or to perform an engagement agreement for legal services. 

6.2 Compliance with Law 
Where the Company is required to comply with laws, court orders, directions of government authorities, or professional requirements. 

6.3 Legitimate Interests 
Where processing is necessary for the legitimate interests of the Company, a Client, or another person, provided that such interests do not disproportionately affect the fundamental rights and freedoms of the Client, including: 

  • Conducting conflict-of-interest checks 
  • Maintaining the security of systems and premises 
  • Managing relationships with Clients 
  • Preventing and investigating fraud 
  • Establishing, exercising, or defending legal claims. 

6.4 Consent 
The Company will request consent where required by law or where no other lawful basis is available. A Client may withdraw consent subject to the conditions prescribed by law. 

6.5 Establishment and Exercise of Legal Claims 
The Company may process sensitive personal data where necessary for the establishment, exercise, performance, or defense of legal claims. 

6.6 Prevention or Suppression of Danger to Life, Body, or Health 
The Company may process personal data in an emergency to protect the life, body, or health of a Client or another person. 

 

7. Consequences of Failing to Provide Personal Data 
Certain personal data is necessary for identity verification, conflict-of-interest checks, entering into contracts, or providing legal services. 
If a Client does not provide required data, the Company may be unable to: 

  • Accept an engagement or provide consultation 
  • Carry out the Client’s instructions or requests 
  • Prepare or submit documents to authorities 
  • Perform contractual or legal obligations 
  • Provide services fully or effectively. 
The Company will inform the Client where particular personal data is mandatory. 

 

8. Disclosure of Personal Data 
The Company will disclose personal data only to the extent necessary and in accordance with the purposes of the relevant services. Personal data may be disclosed to the following persons or organizations: 

8.1 Government Authorities and Statutory Bodies 

  • Courts and court offices 
  • Department of Lands and Land Offices 
  • Department of Business Development 
  • Revenue Department 
  • Immigration Bureau and Immigration Offices 
  • Department of Consular Affairs 
  • Embassies or consulates 
  • Royal Thai Police 
  • Public Prosecutor’s Office 
  • Civil registration authorities 
  • Regulators or authorized officials. 

8.2 Persons Involved in the Provision of Legal Services 

  • Lawyers, legal advisers, or paralegals 
  • Translators, interpreters, or translation certifiers 
  • Notaries public 
  • Contractual parties, opposing parties, witnesses, estate administrators, or representatives 
  • Banks, financial institutions, or insurance companies 
  • Document delivery or document storage service providers. 

8.3 Company Service Providers 

  • Information technology service providers 
  • Data storage or cloud service providers 
  • Email, website, or client-management system providers 
  • Accounting, finance, or payment service providers 
  • Security service providers 
  • Consultants or auditors of the Company. 

The Company will require such service providers to maintain confidentiality and use personal data only for the purposes specified by the Company. 

8.4 Other Persons as Directed or Authorized by the Client 

The Company may disclose personal data to persons designated or authorized by the Client, such as a spouse, relative, representative, broker, or adviser. 
The Company will not sell, rent, or exchange the personal data of Clients for the commercial benefit of third parties. 

 

9. Duty of Confidentiality of a Law Firm 
The Company recognizes that information obtained from Clients or persons seeking legal consultation may be confidential and highly sensitive. 
The Company therefore implements measures to restrict access to personnel and relevant persons who need the information for the performance of their duties and requires those persons to comply with duties of confidentiality under applicable laws, contracts, and professional ethics. 
However, the duty of confidentiality may be subject to exceptions under law, including where the Company is required to disclose information pursuant to a court order, applicable law, or an order of a competent authority. 

 

10. International Transfer of Personal Data 
In providing services to foreign Clients or handling cross-border matters, the Company may need to transfer personal data to: 

  • Embassies or consulates 
  • Foreign lawyers or advisers 
  • Contractual parties or other relevant persons located abroad 
  • Cloud or information technology service providers 
  • Foreign government authorities or financial institutions. 
Where the destination country does not provide an adequate standard of personal data protection as prescribed by law, the Company will implement appropriate and lawful safeguards, such as data protection agreements, obtaining consent, or relying on an applicable legal exception. 

 

11. Retention Period 

The Company will retain personal data only for as long as necessary for the purposes notified, taking into consideration: 

  • The period during which the Company provides services to the Clients 
  • The duration of the contract or legal relationship 
  • Applicable limitation periods or periods for exercising legal claims 
  • Legal document-retention obligations 
  • The need to conduct conflict-of-interest checks 
  • The need to demonstrate advice given or work performed 
  • Accounting, tax, and professional requirements. 
As a general rule, the Company may retain matter files and related documents for at least ten (10) years from the date the relevant matter is closed, or for a longer period where required by law, by the nature of the case or transaction, or for the establishment, exercise, or defense of legal claims. 
When personal data is no longer necessary, the Company will delete, destroy, or anonymize it using appropriate methods, unless applicable law requires or permits continued retention. 

 

12. Security Measures 
The Company implements security measures appropriate to the level of risk and the nature of the personal data, including: 

  • Restricting access rights according to job responsibilities 
  • Using passwords and authentication controls 
  • Using encryption or secure communication channels 
  • Backing up and restoring data 
  • Deploying systems to protect against cybersecurity threats 
  • Storing physical documents in access-controlled locations 
  • Entering into confidentiality agreements 
  • Training personnel on confidentiality and personal data protection 
  • Periodically assessing and reviewing security measures 
  • Maintaining procedures for responding to personal data breaches. 
Although the Company uses appropriate safeguards, the transmission of information over the internet cannot be guaranteed to be completely secure. Clients should therefore avoid sending sensitive information through insecure channels. 

 

13. Rights of Data Subjects 
Subject to the conditions and limitations prescribed by law, Clients have the following rights: 

13.1 Right to Withdraw Consent 
A Client may withdraw consent previously given. Withdrawal will not affect any processing lawfully carried out before the withdrawal. 

13.2 Right of Access 
A Client may request access to and a copy of their personal data and may request disclosure of the source of personal data not provided directly by the Client. 

13.3 Right to Rectification 
A Client may request correction of personal data that is inaccurate, incomplete, outdated, or misleading. 

13.4 Right to Erasure or Destruction 
A Client may request deletion, destruction, or anonymization of personal data where the data is no longer necessary or the Company has no lawful basis for retaining it. 

13.5 Right to Restriction of Processing 
A Client may request restriction of the use of personal data in circumstances prescribed by law, such as while the accuracy of the data is being verified or a deletion request is under consideration. 

13.6 Right to Object 
A Client may object to processing based on legitimate interests or processing for direct marketing purposes. 

13.7 Right to Data Portability 
Subject to the conditions prescribed by law, a Client may request to receive personal data, or request that it be transmitted to another data controller, in a format that is commonly readable or usable by automated means. 

13.8 Right to Lodge a Complaint 
A Client may lodge a complaint with the Personal Data Protection Committee if the Client believes that the Company has processed personal data unlawfully. 
The exercise of certain rights may be restricted or refused where the Company is required to retain or use the data by law, to perform a contract, to protect the confidentiality of another person, or to establish, exercise, or defend legal claims. 

 

14. How to Exercise Data Subject Rights 
A Client may submit a request to exercise their rights by contacting the Company through the channels specified in Section 18. 
The Company may request additional documents or information to verify identity and prevent unauthorized access to the personal data of the Client. 
The Company will consider and respond to the request within the period prescribed by law. If the Company refuses the request, it will inform the Client of the reasons and the right to lodge a complaint. 

 

15. Personal Data of Minors, Incompetent Persons, and Quasi-Incompetent Persons 
Where the Company needs to collect personal data relating to a minor, an incompetent person, or a quasi-incompetent person, the Company will comply with applicable legal requirements, including obtaining consent from a person exercising parental power, a custodian, or a curator where required. 
If a Client becomes aware that the Company has obtained personal data of such a person without proper authority or consent, the Client should notify the Company so that the matter can be reviewed. 

 

16. Third-Party Websites 
The Company’s website may contain links to third-party websites or services. The Company does not control and is not responsible for the manner in which those third parties collect, use, or disclose personal data. 
Clients should read the privacy notices of those websites or service providers before providing personal data. 

 

17. Amendments to this Privacy Notice 
The Company may amend this Privacy Notice from time to time to reflect changes in law, practice, technology, or the Company’s operations. 
The updated Privacy Notice will be published on the Company’s website and will state its effective date or latest revision date. Where a change is material, the Company may also notify Clients through an appropriate additional channel. 

 

18. Contact Details 
If a Client has any questions, comments, complaints, or wishes to exercise any rights relating to personal data, please contact: 

LAFS Legal Co., Ltd. 
Address: 388 Exchange Tower, 29th Floor, Units 2901-2904, Sukhumvit Road, Khlong Toei Subdistrict, Khlong Toei District, Bangkok 10110, Thailand 
Telephone: 02-104-9191 
Email: info@lafs-legal.com 
Website: www.lafs-legal.com

 

Changes to this Privacy Notice 
The Company may update or amend this Privacy Notice from time to time to ensure compliance with personal data protection laws and other applicable laws. Any update will be announced on the Company’s website together with the latest revision date. 

 

Last updated: 4 August 2026 

This website uses cookies to improve its efficiency and for your best browsing experience. Read more about our Cookies Policy as well as our Privacy Policy. You can manage your cookies privacy setting by clicking the Setting button." LAFS Legal Privacy Notice and Cookies Policy
Powered By MakeWebEasy Logo MakeWebEasy